162 Commits

Author SHA1 Message Date
Zuul
3a08123440 Merge "Security Audit Logging of K8S API" 2022-06-28 17:33:35 +00:00
Zuul
e3b7c6cf8d Merge "Debian Tech Preview" 2022-06-28 17:26:23 +00:00
Zuul
e3a5aa8343 Merge "Platform Application Components updates ingress-nginx" 2022-06-28 17:21:12 +00:00
Elisamara Aoki Goncalves
35152799b9 Support for Pod Security Admission Controller - Tech Preview
Added new sections referring to Pod security admission controller

Depends-On: https://review.opendev.org/c/starlingx/docs/+/847094

Story: 2009833
Task: 45631

Signed-off-by: Elisamara Aoki Goncalves <elisamaraaoki.goncalves@windriver.com>
Change-Id: Icbd36b28501edf767a96007d066303da2d0609f4
2022-06-27 23:16:41 -03:00
Ron Stone
df8d634fc8 Debian Tech Preview
Draft Debian preview document
Additional placeholders for conditional content.
Add k8s 1.23 only bullet to Limited Scope topic.
rST rendering fixes.
Address patchset 3 review comments.
Additional operational impacts.
Implement patchset 5 review comments.
Reuse PXE config updates DS.
Address patchset 8 review comments.
Additional patching details.
rST formatting fix.
Complete Known Issues topic.
Fix typo in placeholder name.
Make references to Debian GA version generic.
Fix merge conflict.
Remove trailing space.

Story: 2009965
Task: 45617

Signed-off-by: Ron Stone <ronald.stone@windriver.com>
Change-Id: Iac67113dc7f56209637828a2b807cd65669ec583
2022-06-27 13:53:02 -04:00
Oliver
65a9de5869 Kubernetes custom configuration support
- added review comments from Path Set 2
- added review comments for Patch Set 1
- added updates for jira CGTS-34418
Change-Id: I8013e445b52d3222cbfa6a94939f65a576956f95
2022-06-27 11:22:50 -04:00
Zuul
32ca14806a Merge "Security Planning shall support customer expectations" 2022-06-24 18:40:25 +00:00
Zuul
68e6a5e711 Merge "Certificates expiration date information" 2022-06-24 15:45:18 +00:00
Zuul
236a9f7b89 Merge "Added a Warning Note for the Portieris application" 2022-06-24 01:04:52 +00:00
Oliver
73e7f8ef4c Security Planning shall support customer expectations
Epic: Security Planning shall support expectations presented in pre-sales presentations.
Updated with review comments for Patch set 4
Updated with review comments for Patch set 3
Updated with review comments from Patch set 2
Updated with review comments from Patch set 1
Added summaries of items raised in pre-sales presentations

Change-Id: Ic1e458dfd57ad7ab18923f3a1756007ad717efe1
2022-06-23 14:09:03 -04:00
Elisamara Aoki Goncalves
ac3a23e9f2 Security Audit Logging of K8S API
Story: 2009835
Task: 45636

Signed-off-by: Elisamara Aoki Goncalves <elisamaraaoki.goncalves@windriver.com>
Change-Id: I9b3994baa1dd9aecd8b75f2c1cc8751c66d3db50
2022-06-23 10:35:27 -03:00
Elaine Fonaro
d5adc43774 Certificates expiration date information
Reword and minor update.

Minor updates.

Added extra information about the Alarms link.

Added a note with references regarding how to obtain Certificates expiration data-period information.

Signed-off-by: Elaine Fonaro <elaine.fonaro@windriver.com>
Change-Id: Ic152d5a57effb89534ce269ca0c6a2a8b7f5b5f2
2022-06-23 09:55:16 -03:00
Elisamara Aoki Goncalves
1e0a190aa6 Platform Application Components updates ingress-nginx
Story: 2009836
Task: 45655

Signed-off-by: Elisamara Aoki Goncalves <elisamaraaoki.goncalves@windriver.com>
Change-Id: I93eb5e8e873c29d01d5311a45c252d481c306243
2022-06-23 09:41:59 -03:00
Zuul
ca28c7b1fe Merge "Playbook for managing local ldap admin user" 2022-06-22 20:35:50 +00:00
Juanita-Balaraj
df4cb6c760 Added a Warning Note for the Portieris application
Portieris application is not supported with k8s 1.22 and 1.23

Signed-off-by: Juanita-Balaraj <juanita.balaraj@windriver.com>
Change-Id: Ie67257b1aac24d9fed74a73155d495724cce4886
2022-06-21 18:21:15 -04:00
Pedro Almeida
25f9cc35db Update cert-manager version to v1 from v1alpha2
Following the cert-manager migration to FluxCD, it was upversioned to
v1.7.1 from v0.41.2, which means we need to update our helm-chart
docs to use v1 instead of v1alpha2.

Closes-Bug: #1978858

Signed-off-by: Pedro Almeida <pedro.monteiroazevedodemouraalmeida@windriver.com>
Change-Id: I79955ed7412c0961b315f3b8a8cabd9dfce88fbf
2022-06-21 10:33:38 -03:00
Elisamara Aoki Goncalves
87fa40f233 Platform Application Components updates cert-manager
Story: 2009837
Task: 45638

Signed-off-by: Elisamara Aoki Goncalves <elisamaraaoki.goncalves@windriver.com>
Change-Id: Icd792cc1daea5e2b451f66aa7ac366d627d647d5
2022-06-17 10:46:28 -03:00
Elisamara Aoki Goncalves
b20a6233f2 Platform Application Components updates oidc-dex
Story: 2009838
Task: 45597

Signed-off-by: Elisamara Aoki Goncalves <elisamaraaoki.goncalves@windriver.com>
Change-Id: Ia3a0e3e5308221bc8ad1c66cdbb6b1a6046fc32b
2022-06-13 10:18:12 -03:00
Elisamara Aoki Goncalves
2e8a5f69b0 Playbook for managing local ldap admin user
Story: 2009759
Task: 45440

Signed-off-by: Elisamara Aoki Goncalves <elisamaraaoki.goncalves@windriver.com>
Change-Id: Ic55e2a5852545b3921647ffa5e83833cad82c6cd
2022-06-06 17:29:42 -03:00
Elaine Fonaro
bcc701b0e0 Password command usage is incorrect. (CP r6, dsr6)
Updated the original command: removed the <temp_password> from command.

Minor edits and also removed the <temp\_password> from the comment.

Signed-off-by: Elaine Fonaro <elaine.fonaro@windriver.com>
Change-Id: I876281ef2ddbea9b5df271cc1370b3580277d01e
2022-06-03 09:45:59 -03:00
Zuul
0acad2efc2 Merge "Security Audit Logging" 2022-06-02 16:55:57 +00:00
Ron Stone
d63e42ebeb Security Audit Logging
Continuation of changes made under https://review.opendev.org/c/starlingx/docs/+/832841
(abandoned)
Add conditional text about log access via controllers.
Patchset 3 review updates.
Add conditionalization.

Story: 2009824
Task: 45043

Signed-off-by: Ron Stone <ronald.stone@windriver.com>
Change-Id: I4e9a1a9e0940ffc15a71cea954062d7c42a88e81
2022-05-03 07:34:25 -04:00
Ron Stone
3adaa45e61 Remove mentions to TPM mode on certificate commands
Remove customer documentation of TPM mode of certificate install.
Fix merge conflict

Story: 2009712
Task: 44087

Signed-off-by: Ron Stone <ronald.stone@windriver.com>
Change-Id: Iaf4d0d288181f0feb10af58f3ce361f1a8ea5324
2022-04-27 11:21:44 -04:00
Juanita-Balaraj
8e5ee31aa5 Fixed Broken Link to the Installation Guides (pick stx5, stx 6, dsR6)
Signed-off-by: Juanita-Balaraj <juanita.balaraj@windriver.com>
Change-Id: I867a025843cce12c6d510f194a1b8d213d396c79
2022-03-21 18:13:28 +00:00
Zuul
600e8d5f7e Merge "Playbook to migrate platform certificates to use cert-manager for auto-renewals" 2022-03-14 13:28:37 +00:00
Ron Stone
403e986ed3 Playbook to migrate platform certificates to use cert-manager for auto-renewals
Initial draft content for migration playbook usage.
Incorporate patchset 1 review comments.
Incorporate patchset 2 review comments.
Incorporate patchset 3 review comments.

Story: 2007361
Task: 44350

Signed-off-by: Ron Stone <ronald.stone@windriver.com>
Change-Id: I3617ce10b6416eb8cd714a97cb6411900d7240d2
2022-03-14 10:43:40 +00:00
Ron Stone
bcd642075c Cluster issuer yaml configuration file reports unknown field "organizations" (pick r6)
Remove 'organizations' section from cert-manager sample yaml
Add note in TPM topic indicating that its use should be avoided
Incorporate patchset 1 review comments.

Signed-off-by: Ron Stone <ronald.stone@windriver.com>
Change-Id: I6b293d86e2943bf8e505be486cdad536e946337b
2022-03-09 14:11:38 +00:00
Juanita-Balaraj
e97f60f41f Added auditd include File
Signed-off-by: Juanita-Balaraj <juanita.balaraj@windriver.com>
Change-Id: I0269e35c9b36409a7556920fec8560ae202f3da6
2022-02-17 12:42:33 -05:00
Ron Stone
66aaeca8ab typos in OIDC AUTH DOCS for WRCP 21.12
Codeblock updates

Signed-off-by: Ron Stone <ronald.stone@windriver.com>
Change-Id: I277f17ece1062adc9e7c3c6948c8c4745cdcba4e
2022-01-31 13:11:00 -05:00
Ron Stone
4edefbc227 Unique index names (security)
Make Security index names unique

Signed-off-by: Ron Stone <ronald.stone@windriver.com>
Change-Id: Ia0b5f267ba7c14f5e916d0f685e252c1da1f196c
2022-01-21 08:04:22 -05:00
Zuul
9e8eefbdec Merge "OIDC script updates" 2022-01-11 18:23:55 +00:00
Zuul
a24d9d27f2 Merge "Added warning for K8 Root CA update impact on services" 2022-01-11 12:33:30 +00:00
Juanita-Balaraj
e1b59dde35 Added warning for K8 Root CA update impact on services
Updated Patshet 2 comments
Updated Patchset 1 comments
Signed-off-by: Juanita-Balaraj <juanita.balaraj@windriver.com>
Change-Id: I764232e87edb856e9efd8e353b2527a91b03b70b
2022-01-10 17:24:01 -05:00
Ron Stone
cf98a7c9ea OIDC script updates
Per Teresa H. OIDC CLI access script is part of image and does not need to
be downloaded.
Cleaned up explicit references to DS doenloads location and replaced with
placeholder.
Added note that oidc-auth script needs to be downloaded if used from remote
hosts
Patchset2 review updates

Signed-off-by: Ron Stone <ronald.stone@windriver.com>
Change-Id: I9e713b9c41d8dbe4bad0fe0c2866c913853a79db
2022-01-10 14:05:58 -05:00
Elisamara Aoki Goncalves
7b7af0227e Note added in section Trusted CA certificate
Signed-off-by: Elisamara Aoki Goncalves <elisamaraaoki.goncalves@windriver.com>
Change-Id: Id0a986aa1aacc3f2936b44e43851f7017f2587a0
2022-01-07 15:41:27 -03:00
MCamp859
22f5da9377 Fix gray bar issue
Fix gray bar issue in 1 file.

Change-Id: I8669c8c751da8545d6f96a1f7e9782d7c0bb757c
Signed-off-by: MCamp859 <maryx.camp@intel.com>
2021-12-22 11:22:33 -05:00
Zuul
0b7ab1dd08 Merge "Cert-Manager Use for StarlingX Platform Services" 2021-12-14 18:59:14 +00:00
Ron Stone
3e03a0bc82 Cert-Manager Use for StarlingX Platform Services
Initial draft procedures.
Resolve merge conflicts.
Incorporate patchset 1 review comments.
Incorporate patchset 2 review comments.
Incorporate patchset 3 review comments.
Incorporate patchset 4 review comments. Open questions for J. Sun to be addressed.
Incorporate patchset 5 review comments.
Made sample url used in overrides generic.
Incorporate patchset 8 review comments.
Added note about issuer_root_ca recommended by J. Sun.
Incorporate patchset 10 review comments.
Fix formatting issue in output.
Incorporate patchset 12 review comments.

Story: 2007361
Task: 42625

Signed-off-by: Ron Stone <ronald.stone@windriver.com>
Change-Id: I5a73f902902acc02baccb92995f696a4b19fb773
2021-12-14 11:30:07 -05:00
Elisamara Aoki Goncalves
ee2848e5fa Updates on K8S Root CA Certificate managed by cert-manager
Updated output

Editorial fixes

Merged sections

Fixed typos and indentation

Updated sections titles

Reordered sections in index

Fixed minor grammar issues

Added alarms exception

Described syntax of subject and expiry_date in example

Added references

Replaced K8s for Kubernetes

Story: 2008675
Task: 42625

Signed-off-by: Elisamara Aoki Goncalves <elisamaraaoki.goncalves@windriver.com>
Change-Id: I178fe9747c558d13c05b5cf61271fcaff59f6c26
2021-12-13 01:33:32 -03:00
Zuul
abc3bfa93a Merge "Updated Controller Swact commands" 2021-12-09 19:05:31 +00:00
Juanita-Balaraj
22ca60110f Updated Controller Swact commands
Updated Patchset 1 comments
Signed-off-by: Juanita-Balaraj <juanita.balaraj@windriver.com>
Change-Id: If33da881a4dcc16cc3366e4361fd4d6247192ace
2021-12-09 18:43:49 +00:00
Zuul
cb8e03861a Merge "Service parameters deprecated and not being used by puppet manifests" 2021-12-08 22:14:45 +00:00
Zuul
bce970450d Merge "Separate CA for etcd" 2021-12-08 22:09:30 +00:00
Elisamara Aoki Goncalves
483a8196d6 Service parameters deprecated and not being used by puppet manifests
Applied formatting changes

Closes-bug: 1950490

Signed-off-by: Elisamara Aoki Goncalves <elisamaraaoki.goncalves@windriver.com>
Change-Id: Iaae1f1d93cc2c3be993781b0d1250b4214148d16
2021-12-07 17:51:59 -03:00
Zuul
72f8fab056 Merge "Add a note for remotecli section when the https is enabled on the system" 2021-12-06 18:59:50 +00:00
Ron Stone
ecfd58375d Add a note for remotecli section when the https is enabled on the system
Added said note as a prereq.
Cleaned up some incidental formatting errors.
Incorporated patchset 1 review comments.
Incorporated patchset 2 review comments.
Incorporated patchset 3 review comments.

Signed-off-by: Ron Stone <ronald.stone@windriver.com>
Change-Id: I0e2096eb999e2a156d82680e340f769cf33acdd8
2021-12-06 07:08:10 -05:00
Elisamara Aoki Goncalves
738cb1e463 Separate CA for etcd
Removed note and changed place of the new text

Fixed certificates expiration date

Fixed certificate name

Added certificate validity to a note

Rewrote sentence to make content more clear

Story: 2008833
Task: 43600

Signed-off-by: Elisamara Aoki Goncalves <elisamaraaoki.goncalves@windriver.com>
Change-Id: Ibd1fe52eb4e014217b8d36e4ab3761cdbe8a71d5
2021-11-30 21:03:40 +00:00
Zuul
22359d5bd9 Merge "Alarm Expiring or Expired Certificates" 2021-11-29 20:06:23 +00:00
Zuul
67880814b0 Merge "Removed lock/unlock the controllers and subclouds after the keystone admin password change." 2021-11-26 17:52:52 +00:00
Ron Stone
52b70f81c2 Alarm Expiring or Expired Certificates
Added topic on new expiring/expired cert alarms.
Added 2x alarms to 500 series alarms messages page. NB. Details need to be confirmed.
Minor update for clarity around use of kubernetes edit ...
Added sample fm output
Updtes to alarm definitions based on events.yaml
Incorporated (Word) updates from Greg W.
Patchset 4 review updates.
Patchset 5 review updates.
Fixed merge conflict in sec/kub/index
Patchset 7 review updates.
Patchset 8 review update (note about cert expiry check frequency)

Story: 2008946
Task: 43568

Signed-off-by: Ron Stone <ronald.stone@windriver.com>
Change-Id: Ifeeba7484e49abcaf2d1ad2afc9afc876d479ded
2021-11-26 11:09:14 -05:00